Most proposals are not lost on the quality of their writing. They are lost on technicalities: a mandatory requirement that went unanswered, a form that was not submitted, a page limit that was breached. A compliance matrix exists to make sure that never happens.
It is the single most important artifact in a response, and it should be built before anyone writes a word of narrative. The APMP Body of Knowledge is direct on this point: prepare a comprehensive compliance matrix for every bid request, build it early, and shred the requirements line by line rather than by section.
If it is not in the matrix, it is not in the proposal. The matrix is the proof that nothing was missed.
What a compliance matrix is
A compliance matrix is a checklist and a map in one document. As a checklist, it confirms that every requirement in the solicitation has been addressed. As a map, it shows where in the response each requirement is answered, so reviewers and evaluators can trace it quickly.
It does two jobs at once:
- For your team: it turns a dense solicitation into an owned, trackable task list, so nothing is missed and responsibility is clear.
- For the evaluator: it makes the proposal easy to score, because every requirement can be located without hunting through the document.
A compliant proposal meets the stated requirements and submission instructions to the letter. A responsive proposal also answers the buyer’s underlying need. Winning proposals are both, and the compliance matrix is where compliance is guaranteed.
Build it before you write
The most common mistake is treating the matrix as an afterthought – something assembled near submission to check the work. By then it is too late to catch a missed requirement without a last-minute scramble.
Build the matrix in the planning phase, before drafting:
- It becomes the plan of action that assigns writers to requirements.
- It surfaces gaps while there is still time to fill them.
- It anchors the review gates, because reviewers check against the matrix, not from memory.
Treat a comprehensive compliance matrix as mandatory for every bid, regardless of size or timeline. See How to Respond to an RFP for where it sits in the wider process.
How to shred the RFP
“Shredding” means extracting every obligation into its own row. Do not summarize by section or paragraph; that is how requirements hide. Capture each one separately, and follow the buyer’s own numbering so the evaluator can score against it.
Hunt for the words that carry obligation:
| Term | What it means | How to treat it |
|---|---|---|
| shall / must | A mandatory requirement | Scored or pass/fail; never optional |
| should | A stated goal | Must be addressed, but not formally verified |
| will | Often a statement of fact about the buyer | Read carefully; usually not an obligation on you |
| may | A permission, not a requirement | Note it, but do not over-commit |
Attach an owner and a response location to every row. A requirement without an owner is a requirement that will be missed.
Minimum fields for your matrix
You can start with a spreadsheet and a handful of columns. Add sophistication only when it earns its place.
| Field | Purpose |
|---|---|
| Requirement ID | Stable reference for tracking and reviews |
| Source (section / page) | Traceability back to the solicitation |
| Requirement text | The verbatim obligation |
| Type | Submission, technical, management, pricing, format |
| Pass/fail flag | Marks disqualifiers that must be closed first |
| Owner | One accountable person per requirement |
| Status | Open, drafted, reviewed, closed |
| Response location | Where the answer lives (volume / section) |
| Evidence reference | The proof point or data supporting the claim |
For a ready-to-use starting point, download the Compliance Matrix Template.
Do not miss the hidden requirements
Not every requirement is labeled with a “shall.” A substantial share of disqualifications comes from obligations buried in narrative, instructions and evaluation criteria. Capture:
- Format and packaging rules, including page limits and font requirements.
- Submission mechanics: portal, file naming, file types, upload sequence and deadline time zone.
- Mandatory forms, declarations and signatures – and where they go.
- Content placement instructions (“provide the staffing plan in Volume 2, Section 3”).
- Amendment-driven changes, which must be absorbed into the matrix as they arrive.
- The evaluation criteria, which tell you where the score actually sits.
Automated extraction can accelerate the first pass, but the matrix must be reconciled to the solicitation by a human. Keep a visible list of the hidden requirements you found, so a reviewer can confirm that none were missed when the response is checked. For how AI fits safely, see Using AI for RFP Requirement Mapping.
Keep it live to submission
A compliance matrix is a living document, not a planning artifact. Update it throughout the response as amendments arrive, clarification answers change the scope, and the outline evolves. Two disciplines keep it trustworthy:
- Reconcile in both directions. Walk the matrix against the RFP to catch what was missed, and against the response to confirm every requirement has a home.
- Close every pass/fail item first. Disqualifiers should be shut down before effort goes into the narrative.
Submit a response matrix too
Many teams run the matrix as an internal control and stop there. Consider also submitting a response matrix with the proposal: a short table that points the evaluator to where each requirement is answered. Even when it is not required, it makes the proposal easier to score – and easier-to-score proposals are rewarded.
A worked example of shredding
Shredding is easier to show than to describe. Imagine a short services RFP with three sections: instructions, a statement of work, and evaluation criteria.
- From the instructions: “Proposals must not exceed 20 pages per volume.” → Format requirement, pass/fail, owner: editor. “Submit via the portal by 2:00 p.m. ET.” → Submission requirement, owner: proposal lead.
- From the statement of work: “The provider shall provide a named transition manager for the first 90 days.” → Technical/management requirement, owner: solution lead. “The provider must hold a current SOC 2 Type II report.” → Compliance requirement, pass/fail, owner: security lead.
- From the evaluation criteria: “Approach will be scored out of 30 points.” → Not a requirement, but it tells you where the score sits and where your best evidence must land.
Three passes over three sections produce a traceable list with owners and a clear view of the disqualifiers. What it also shows is that the most dangerous rows – the SOC 2 requirement, the page limit, the submission time – are not the ones a writer would naturally focus on. That is precisely why the matrix exists.
Common mistakes
- Shredding by section instead of by requirement. Requirements hide inside paragraphs. One row per obligation, always.
- Ignoring format and submission rules. They are pass/fail, and they disqualify more bids than weak narrative.
- No owner per row. An unowned requirement is a requirement that gets missed.
- Skipping hidden requirements. Instructions, evaluation criteria and amendments contain obligations that are never labeled “shall.”
- Freezing the matrix at planning. It must absorb every amendment and clarification answer through to submission.
Who owns the matrix, and where it lives
The matrix belongs to the proposal manager or bid lead – the person accountable for compliance. It should live in one place everyone works from: a shared spreadsheet or the proposal tool, never multiple copies in inboxes. Writers need access to their rows; the owner controls status. As the response progresses, the matrix is the single source of truth for what is still open, which makes it the natural basis for the review gates. If two versions of the matrix exist, neither can be trusted and the control collapses. Set a weekly status pass so open pass/fail items are closed first, and keep the matrix visible in every review meeting so it stays a live control rather than a planning artifact.
Frequently asked questions
What is a compliance matrix?
A structured table that lists every requirement in a solicitation, assigns an owner and a response location, and tracks whether each requirement has been addressed. It is both a checklist for your team and a map for evaluators.
When should you build a compliance matrix?
Before you start writing – in the planning phase. It becomes the plan of action for writers and the basis for review. Building it near submission is too late to catch most gaps.
Do you need a compliance matrix for every bid?
Yes. The APMP recommends a comprehensive compliance matrix for every bid request regardless of size or timeline. The smaller the bid, the less time you have to notice something missing.
What is the difference between a compliance matrix and a response matrix?
A compliance matrix is usually internal, tracking ownership and status. A response matrix is a derivative submitted with the proposal that points the evaluator to where each requirement is answered. Many teams build the first and optionally submit the second.
How do you handle a requirement you cannot meet?
Flag it early as a hard gate. If it is mandatory, the opportunity may be a no-bid; if it is negotiable, address it explicitly with a clear mitigation rather than ignoring it and hoping the evaluator does not notice.
What do “shall,” “should” and “will” mean in an RFP?
“Shall” and “must” are mandatory requirements to be met and, often, scored. “Should” is a goal to be addressed but not formally verified. “Will” is usually a statement of fact about the buyer rather than an obligation on you. When the usage is ambiguous, ask for clarification early.
Should the compliance matrix be a spreadsheet or part of a tool?
Either works. A spreadsheet is enough for most bids and is easy to share; a proposal tool adds tracking and sign-off for teams bidding at volume. What matters is one authoritative version, an owner, and a status per row. The format matters far less than the discipline of keeping it current.
Next step
A compliance matrix protects you from the losses that have nothing to do with the quality of your thinking. Download the Compliance Matrix Template, build it early on your next bid, and run a red-team review against it before submission – see Red-Team Your Proposal for the protocol. If you want an independent check, request a red-team review.
Sources
- APMP, Body of Knowledge and Proposal Specialist Certification Guide: compliance matrix, requirement shredding (shall / must / should / will), compliance and responsiveness, and submitting a response matrix.
- APMP Western Region, “Shred for Success – The Value of a Compliance Matrix”: line-by-line shredding, hidden requirements, and keeping the matrix current.
- APMP, Winning Business Ecosystem: RFP review and compliance tracking as the foundation of the response.
Numbers and good-practice claims are cited from their sources; no statistic in this article is invented.